Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New XCSSET Malware Variant Targets macOS App Developers

Cybersecurity researchers have identified an advanced variant of the XCSSET malware targeting macOS developers through infected Xcode projects. This variant introduces sophisticated clipboard hijacking and enhanced data exfiltration capabilities.

Cybersecurity researchers have identified an advanced variant of the XCSSET malware targeting macOS developers through infected Xcode projects. This variant introduces sophisticated clipboard hijacking and enhanced data exfiltration capabilities.

Microsoft Threat Intelligence has detected a new XCSSET variant that includes further updates and new modules beyond previous analyses. The malware infects Xcode projects, commonly used by software developers, and operates during the build process of an Xcode project.

This variant of XCSSET brings notable changes related to browser targeting, clipboard hijacking, and persistence mechanisms. It employs advanced encryption and obfuscation techniques, utilizes run-only compiled AppleScripts for stealthy execution, and expands its data exfiltration capabilities to include Firefox browser data.

The malware also introduces another persistence mechanism through LaunchDaemon entries, complicating detection and removal.

The latest XCSSET variant follows a four-stage infection chain, with the fourth stage introducing several new malicious modules. The vexyeqj info-stealer module downloads and executes a run-only compiled AppleScript called "bnk," which performs sophisticated clipboard monitoring and cryptocurrency wallet hijacking.

This module uses AES encryption with a hardcoded key to decrypt configuration data from command and control servers. The clipboard hijacking functionality is particularly advanced, verifying the clipboard content against cryptocurrency wallet address patterns and replacing legitimate addresses with attacker-controlled alternatives.

A new iewmilh_cdyd module targets Firefox browser data, downloading a modified version of the HackBrowserData project. This binary extracts passwords, browsing history, credit card information, and cookies from Firefox installations. The data is compressed into ZIP files and sent to command and control servers.

The neq_cdyd_ilvcmwx file-stealer module retrieves additional scripts from command and control servers and operates as a compiled AppleScript, similar to previous wallet data stealers but with enhanced file exfiltration capabilities.

The xmyyeqjx module establishes LaunchDaemon-based persistence by creating a ~/.root file and associated plist entries, masquerading as legitimate system processes. This module also disables macOS automatic updates and Rapid Security Response mechanisms, weakening system defenses.

Security experts recommend maintaining updated operating systems and applications, inspecting Xcode projects from external sources, and handling clipboard data with caution, especially cryptocurrency addresses.

Cybersecurity researchers have identified an advanced variant of the XCSSET malware targeting macOS developers through infected Xcode projects.
Natalie Rhodes · Thehackingpost

Microsoft suggests using browsers with SmartScreen protection, deploying Microsoft Defender for Endpoint on Mac, and enabling cloud-delivered protection with automatic sample submission. Network protection should be activated to block connections to malicious domains associated with this campaign.

Indicator Type Description

cdntor[.]ru Domain C2 server

checkcdn[.]ru Domain C2 server

cdcache[.]ru Domain C2 server

applecdn[.]ru Domain C2 server

flowcdn[.]ru Domain C2 server

elasticdns[.]ru Domain C2 server

Advertisement

rublenet[.]ru Domain C2 server

figmastars[.]ru Domain C2 server

bulksec[.]ru Domain C2 server

dobetrix[.]ru Domain C2 server

figmacat[.]ru Domain C2 server

digichat[.]ru Domain C2 server

diggimax[.]ru Domain C2 server

cdnroute[.]ru Domain C2 server

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories